Emergency server help: get in touch

Domain Controller Metadata Cleanup: Safely Demote or Remove a Dead DC

Demote a working domain controller with Uninstall-ADDSDomainController, or remove a failed one with forced removal, FSMO seizure and metadata cleanup in ADUC, Sites and Services or ntdsutil, then clean DNS and verify with dcdiag and repadmin.

Published Updated 13 min read

Domain controller metadata cleanup removes every trace of a DC that no longer exists: its NTDS Settings object, computer account, replication connections, DFSR membership for SYSVOL and the DNS records that still send clients to it. You need it whenever a DC dies, is rebuilt, or is forcibly demoted. This guide first covers the clean path, a graceful demotion, and then the forced removal, FSMO seizure, metadata cleanup and DNS cleanup for a DC that cannot be demoted normally.

Short answer: If the DC still works and can reach another DC, run Uninstall-ADDSDomainController (or Server Manager’s Demote this domain controller) and no cleanup is needed. If the DC is dead, seize its FSMO roles with Move-ADDirectoryServerOperationMasterRole -Force, delete its computer object in Active Directory Users and Computers with the “permanently offline” checkbox ticked, remove its leftover DNS records, and confirm with repadmin /replsummary and dcdiag.

Which method to use

SituationMethodMetadata cleanup needed?
DC is healthy and can replicate with a partnerGraceful demotion (Server Manager or Uninstall-ADDSDomainController)No, demotion removes its objects
DC is the last one in the domainGraceful demotion with -LastDomainControllerInDomainNo, the domain is removed
DC boots but cannot reach any other DCForced removal (-ForceRemoval)Yes, on the remaining DCs
DC is dead, deleted or will never returnNo demotion possible; seize roles and clean upYes
DC restored from an old snapshot, USN rollbackForced removal, cleanup, then re-promoteYes

Forced removal loses every change that existed only on that DC and leaves orphaned metadata behind. Microsoft notes that orphaned metadata is behind a significant share of its AD DS support cases, so treat domain controller metadata cleanup as mandatory after any forced removal.

What metadata cleanup removes

Every DC is represented in several places in Active Directory. A graceful demotion removes them all; a dead DC leaves them behind. Domain controller metadata cleanup deletes:

  • The NTDS Settings object under the server object in CN=Sites,CN=Configuration, which tells the Knowledge Consistency Checker (KCC) that the DC exists and should receive replication.
  • The inbound and outbound connection objects other DCs created to replicate with it.
  • The DC’s computer account in the Domain Controllers OU, and the FRS or DFSR member objects that made it part of SYSVOL replication.
  • References that make the DC a FSMO role holder, which the cleanup offers to transfer or seize.

Until these objects are gone, the remaining DCs keep trying to replicate with the missing server. You see replication errors such as 1722 (RPC server unavailable) or 8524 (DNS lookup failure), KCC warnings in the Directory Service log, and dcdiag failures that hide real problems. Some applications, including Exchange and older backup agents, also read the list of DCs from the Configuration partition and try the dead one.

Plan the removal

Whether you demote or run domain controller metadata cleanup, answer these questions first and write the answers in the change record:

  1. Which roles does the DC hold? Check FSMO roles (netdom query fsmo), global catalog, DNS, DHCP, certificate services, NPS and any file shares.
  2. Which clients use it directly? Look at DHCP scopes, static DNS settings on servers, LDAP bind settings in applications and appliances, and time synchronisation.
  3. Which site will lose its only DC? Clients there will authenticate across the WAN; decide whether that is acceptable.
  4. Is replication healthy on the remaining DCs? Fix existing errors first, or the cleanup will be harder to verify.

Prerequisites

  • Domain Admins membership for DCs in the domain; Enterprise Admins to remove the last DC of a child domain, seize the schema or domain naming master, or remove application partitions.
  • The RSAT AD DS tools and the ActiveDirectory PowerShell module on the machine you work from.
  • At least one other healthy DC in the domain that is a global catalog and DNS server. Check with Get-ADDomainController -Filter * | Select-Object Name, Site, IsGlobalCatalog, OperationMasterRoles.
  • A recent system state backup of a remaining DC.
  • Clients and member servers that list the old DC as a DNS server must be updated first (DHCP option 006, static NIC settings, conditional forwarders, and appliances such as firewalls or printers that use LDAP).

Method 1: graceful demotion

Before you start

  1. Move FSMO roles off the DC. Demotion transfers them automatically, but choosing the target yourself is cleaner:
    Get-ADDomainController -Identity DC01 | Select-Object OperationMasterRoles
    Move-ADDirectoryServerOperationMasterRole -Identity DC02 -OperationMasterRole PDCEmulator, RIDMaster, InfrastructureMaster

    In this guide DC01 is the server being removed and DC02 is the surviving DC; -Identity names the DC that receives the roles.
  2. If it is a global catalog, make sure another DC in the same site is one too.
  3. If it holds the PDC emulator, reconfigure the new PDC as the authoritative time source.
  4. Check replication is healthy: repadmin /replsummary should show no failures.

Demote with PowerShell

Run a pre-check first, then the demotion. You are prompted for a new local Administrator password, which the server uses once it becomes a member server:

Test-ADDSDomainControllerUninstallation
Uninstall-ADDSDomainController -Credential (Get-Credential CONTOSO\admin)

The server restarts as a member server. Remove the role binaries afterwards:

Uninstall-WindowsFeature -Name AD-Domain-Services -IncludeManagementTools -Restart

Useful switches:

ParameterWhat it does
-LastDomainControllerInDomainStates that this is the last DC, which removes the domain
-RemoveApplicationPartitionsRemoves application partitions (for example DNS partitions) hosted only here
-RemoveDnsDelegationRemoves DNS delegations pointing to this server from the parent zone
-IgnoreLastDnsServerForZoneContinues even if this is the last DNS server for an AD-integrated zone
-DemoteOperationMasterRoleLets a forced demotion continue when the DC still holds FSMO roles
-ForceRemovalRemoves AD DS without contacting other DCs (Method 2)
-NoRebootOnCompletionSuppresses the restart; Microsoft recommends it only for testing

Demote with Server Manager

  1. In Server Manager, choose Manage » Remove Roles and Features and select the server.
  2. Untick Active Directory Domain Services. When prompted, click Remove Features, then Demote this domain controller in the validation message.
  3. In the AD DS Configuration Wizard, supply credentials. Leave “Force the removal of this domain controller” unticked, unless the DC cannot contact any other DC.
  4. Tick Last domain controller in the domain only if that is true. Confirm the warnings about DNS and global catalog roles.
  5. Enter a new local Administrator password, review the summary and click Demote. After the restart, run the wizard again to remove the AD DS role itself.

Last DC in the domain

Demoting the final DC removes the domain from the forest. For a child domain, you need Enterprise Admins credentials and the parent domain’s DCs must be reachable. Remove any member computers and trusts first, and use -LastDomainControllerInDomain -RemoveApplicationPartitions. For the last DC in the forest, the forest itself disappears; take a final backup and make sure nothing depends on it, because there is no undo.

Method 2: forced removal

Use forced removal only when the DC still starts but has no way to reach another DC, for example after a site was permanently disconnected or the server was restored from an old snapshot.

Uninstall-ADDSDomainController -ForceRemoval -DemoteOperationMasterRole -Force

In Server Manager, tick “Force the removal of this domain controller”. The server becomes a workgroup or member server, but the rest of the domain still believes the DC exists. Continue with FSMO seizure (if it held roles) and domain controller metadata cleanup on a surviving DC.

Seize FSMO roles from a dead DC

If the failed DC held operations master roles, seize them onto a healthy DC before or during cleanup. Transfer is impossible because the old holder cannot respond. Seizing is permanent: the old DC must never come back online with those roles.

PowerShell

netdom query fsmo
Move-ADDirectoryServerOperationMasterRole -Identity DC02 -OperationMasterRole SchemaMaster, DomainNamingMaster, PDCEmulator, RIDMaster, InfrastructureMaster -Force

Run the command against a DC in the same domain for the PDC emulator, RID master and infrastructure master roles; the schema and domain naming master roles are forest-wide and need Enterprise Admins rights.

ntdsutil

ntdsutil
roles
connections
connect to server DC02
quit
seize schema master
seize naming master
seize rid master
seize pdc
seize infrastructure master
quit
quit

Seize only the roles the dead DC held. Seizing the RID master deliberately skips a block of RIDs to avoid duplicates, which is expected. The new holder waits for one successful inbound replication of the relevant partition before it acts on the role.

Method 3: domain controller metadata cleanup

Since Windows Server 2008, deleting a DC object with the GUI performs metadata cleanup for you, including the NTDS Settings object and the SYSVOL DFSR membership. Pick one of the three options below and run it against a surviving DC that was a replication partner of the removed one.

Option A: Active Directory Users and Computers

  1. Open Active Directory Users and Computers and connect to a healthy DC.
  2. Open the Domain Controllers OU, right-click the dead DC and choose Delete, then confirm.
  3. In the Deleting Domain Controller dialog, tick “This Domain Controller is permanently offline and can no longer be demoted using the Active Directory Domain Services Installation Wizard (DCPROMO)” and click Delete.
  4. If it was a global catalog, confirm with Yes. If it still held FSMO roles, click OK to move them to the DC shown.

If Delete is greyed out, the object is protected from accidental deletion. Enable View » Advanced Features, open the object’s Object tab and clear the protection checkbox.

Option B: Active Directory Sites and Services

  1. Open Active Directory Sites and Services and expand Sites » <site> » Servers » <DC name>.
  2. Right-click NTDS Settings, choose Delete and tick the same “permanently offline” checkbox.
  3. Once NTDS Settings is gone, right-click the server object itself and delete it. If other child objects remain under it (for example from another application), leave the server object in place.

Always check Sites and Services after Option A as well: the server object often stays behind in the site and should be removed as the last step of domain controller metadata cleanup.

Option C: ntdsutil

Use ntdsutil on Server Core or when the GUI refuses. The remove selected server command takes the distinguished name of the server object:

ntdsutil
metadata cleanup
connections
connect to server DC02
quit
remove selected server "CN=DC01,CN=Servers,CN=HQ,CN=Sites,CN=Configuration,DC=contoso,DC=com"
quit
quit

Confirm the Server Remove Configuration dialog. If ntdsutil reports that the object cannot be found, the metadata was already removed. Find the correct DN with Get-ADObject -SearchBase (Get-ADRootDSE).configurationNamingContext -Filter "objectClass -eq 'server' -and name -eq 'DC01'".

Clean up DNS records

Domain controller metadata cleanup does not always remove every DNS record the old DC registered. Leftover records make clients try the dead DC first, which slows logons and breaks some applications. In DNS Manager on a surviving DC, check each of these:

LocationRecord
contoso.com zoneA/AAAA record for the DC name, and the same-as-parent A record holding its IP
contoso.com zone properties » Name ServersNS entry for the dead DC
_msdcs.contoso.com zoneCNAME named after the DC’s DSA GUID; NS entry; gc._msdcs A record
_msdcs.contoso.com » dc, gc, pdc, domainsSRV records (_ldap, _kerberos) pointing to the DC
contoso.com » _sites, _tcp, _udpSRV records for _ldap, _kerberos, _kpasswd, _gc
Parent zone (child domains) and reverse lookup zonesDelegation NS records and PTR records

PowerShell makes the search easier. The example lists every record in the domain zone that points to the old DC’s name or IP address:

$zone = 'contoso.com'
Get-DnsServerResourceRecord -ZoneName $zone -ComputerName DC02 |
  Where-Object { $_.RecordData.DomainName -like 'dc01.*' -or $_.RecordData.NameServer -like 'dc01.*' -or $_.RecordData.HostNameAlias -like 'dc01.*' -or $_.RecordData.IPv4Address -eq '10.0.0.10' } |
  Format-Table HostName, RecordType, RecordData -AutoSize

Repeat for _msdcs.contoso.com, review the list, then remove each record with Remove-DnsServerResourceRecord or in DNS Manager. The nltest /dsderegdns:dc01.contoso.com command can also deregister the DC’s records when run on a DC.

SYSVOL and DFSR membership

SYSVOL on Windows Server 2016 and later replicates with DFSR. Deleting the DC object through the GUI or ntdsutil removes its member object in the Domain System Volume replication group. Check in ADSI Edit or with PowerShell that nothing is left:

Get-ADObject -SearchBase "CN=Topology,CN=Domain System Volume,CN=DFSR-GlobalSettings,CN=System,DC=contoso,DC=com" -Filter * |
  Select-Object Name, DistinguishedName

If a member object named after the old DC remains, delete it. Also remove the old DC from any DFS Namespaces and custom DFS Replication groups it served.

Verify it works

repadmin /replsummary
repadmin /showrepl * /csv > C:\Temp\showrepl.csv
dcdiag /e /v /q
nltest /dclist:contoso.com
Get-ADDomainController -Filter * | Select-Object Name, Site, OperationMasterRoles
netdom query fsmo
  • repadmin /replsummary must no longer list the old DC as a source or destination.
  • dcdiag /e /q tests every DC in the enterprise and prints only errors; the old DC must not appear.
  • nltest /dclist and Get-ADDomainController show only the remaining DCs.
  • Resolve-DnsName -Type SRV _ldap._tcp.dc._msdcs.contoso.com returns only live DCs.

Troubleshooting

SymptomCauseFix
Demotion fails: cannot contact another DCDNS points only to itself or partner unreachableSet DNS to a partner DC; if still unreachable, use forced removal
Delete is greyed out in ADUCProtected from accidental deletionClear the protection flag on the Object tab (Advanced Features)
Replication errors 1722 or 8524 still name the old DCConnection objects or DNS records remainDelete stale connection objects in Sites and Services; clean DNS records
Seized role reverts or shows the old DCOld DC came back onlineKeep it offline permanently; wipe and reinstall before reuse
Clients log on slowly after removalSRV or A records still point to the old DCRemove records in _msdcs, _sites, _tcp and the zone root
“Object cannot be found” in ntdsutilWrong DN or already cleanedLook up the server object DN in the Configuration partition

Reusing the old server

A DC that was forcibly removed or had its roles seized must not rejoin the network as it is. Wipe and reinstall it, or at least complete the forced removal on it before connecting it. Then, after domain controller metadata cleanup has replicated everywhere, give it a new name (or wait for replication before reusing the old one), join the domain and promote it as a new DC.

Domain controller metadata cleanup at a glance

Domain Controller Metadata Cleanup summary card: If the DC still works and can reach another DC, run Uninstall-ADDSDomainController (or Server Manager's Demote this…
In short: If the DC still works and can reach another DC, run Uninstall-ADDSDomainController (or Server Manager’s Demote this domain controller) and no cleanup is needed.

Official documentation: Demoting domain controllers and domains, Clean up Active Directory Domain Controller server metadata, Transfer or seize Operation Master roles in AD DS.

Related guides: Transfer FSMO Roles with PowerShell and ntdsutil: Safe Steps · dcdiag repadmin Health Check: 7 Critical Tests Explained · Install and promote a Windows Server 2025 domain controller step by step.

Frequently asked questions

Do I need metadata cleanup after a normal demotion?

No. A graceful demotion removes the DC’s NTDS Settings object, computer account role and DNS registrations itself. Domain controller metadata cleanup is required after forced removal or when a DC dies and cannot be demoted.

Should I seize FSMO roles before or after metadata cleanup?

Seize them first on a healthy DC with Move-ADDirectoryServerOperationMasterRole -Force or ntdsutil. Deleting the DC in Active Directory Users and Computers also offers to move remaining roles, but seizing deliberately lets you choose the target.

Can a DC whose roles were seized come back online?

No. Microsoft advises never returning it to the network as a DC. Reinstall the operating system or forcibly demote it offline, clean up its metadata, and only then promote it again if you need it.

Does metadata cleanup remove DNS records?

Not reliably. Check the domain zone, the _msdcs zone, the _sites, _tcp and _udp SRV records, name server entries and reverse zones for records that still point to the old DC, and delete them.

What is the ntdsutil syntax for metadata cleanup?

Run ntdsutil, metadata cleanup, connections, connect to server with a healthy DC, quit, then remove selected server followed by the distinguished name of the old DC’s server object in the Configuration partition.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.